Security Operations & Monitoring Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Operations & Monitoring flashcards as text
Which NIST document provides guidance on security and privacy controls for federal information systems and organizations?
Answer: NIST SP 800-53
NIST SP 800-53 provides a catalog of security and privacy controls for federal information systems and organizations.
A security analyst notices repeated failed login attempts followed by a successful login from an unusual geographic location. This pattern most likely indicates:
Answer: A credential stuffing or brute-force attack succeeded
Repeated failed attempts followed by success from an unusual location is a hallmark indicator of a credential-based attack that succeeded.
Under the RMF, which step involves assessing whether the security controls selected are implemented correctly and operating as intended?
Answer: Assess
The Assess step involves evaluating whether controls are implemented correctly, operating as intended, and producing the desired outcome.
What is the primary purpose of a Plan of Action and Milestones (POA&M)?
Answer: Track remediation of identified security weaknesses
A POA&M documents identified security weaknesses and tracks the planned remediation actions and target completion dates.
Which log source would be MOST useful when investigating potential insider threat activity involving unauthorized data exfiltration?
Answer: Data Loss Prevention (DLP) alerts
DLP systems monitor and alert on data movements that violate policy, making them the most direct source for identifying data exfiltration.
In continuous monitoring, what does the term 'ongoing authorization' replace in the traditional RMF approach?
Answer: The periodic reauthorization cycle
Ongoing authorization replaces the traditional fixed three-year reauthorization cycle with real-time risk management through continuous monitoring.
Which metric is MOST important for measuring the effectiveness of a security monitoring program?
Answer: Mean Time to Detect (MTTD) security incidents
Mean Time to Detect measures how quickly threats are identified, directly reflecting the effectiveness of monitoring capabilities.